CVE-2020-11007

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-11007
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-11007.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-11007
Aliases
Published
2020-04-16T19:15:26Z
Modified
2024-10-11T10:10:44Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

In Shopizer before version 2.11.0, using API or Controller based versions negative quantity is not adequately validated hence creating incorrect shopping cart and order total. This vulnerability makes it possible to create a negative total in the shopping cart. This has been patched in version 2.11.0.

References

Affected packages

Git / github.com/shopizer-ecommerce/shopizer

Affected ranges

Type
GIT
Repo
https://github.com/shopizer-ecommerce/shopizer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed